The people who drained Blockstream’s Liquid Network last weekend are no longer content to negotiate in private. After days of PGP-encrypted notes stuffed into Bitcoin transactions, they have switched to plaintext, accused Blockstream of skimping on security, and demanded a 10% bounty paid from the company’s own money.
As previously reported, a software bug in Liquid’s Elements node software let an attacker mint unbacked L-BTC on Sunday and cash it out through SideSwap for roughly 4,000 bitcoin, then worth about $320 million. The Liquid Network is a sidechain of Bitcoin that enables features different from the base network and is backed by a federation of members via a base layer multisig Bitcoin address. To be clear, federation keys were not stolen. Vulnerable nodes treated the fake coins as valid, and the federation’s signers released real bitcoin from the 11-of-15 multisig wallet that backs the sidechain.
The attackers labeled themselves white hats in an OP_RETURN message published to the Bitcoin blockchain following the hack, which led to on-chain negotiations with Blockstream. Later, the hackers sent 3,400 bitcoin back to the Liquid federation after bridge nodes were patched, but they kept 598.5 bitcoin, worth around $47 million, from the initial transaction that drained the Liquid federation of nearly all of its bitcoin reserves.
Negotiations Move Into the Open
Encrypted OP_RETURN traffic between the two sides continued after that return. However, there was a public hint that talks were souring early on when the hackers sent a two-character plaintext note: “:(”.
The attackers later made the new ground rules explicit. “All messages will be in plaintext,” they wrote into a Bitcoin transaction while still holding the remaining 598.5 bitcoin. The next public message was an ultimatum. “Your dereliction of duty is obvious that you allocated only $1.5M (maybe even 0) to secure $5B assets,” the attackers wrote. “This is a flagrant neglect of security and a sign of complete mismanagement. You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess.”
negotiations for the remaining 598.5 BTC are going well https://t.co/YEpKv91sEp pic.twitter.com/vgk60Lhcsl
— mononaut (@mononautical) September 9, 2026
They added, “Even companies that participate in bug bounty programs cannot guarantee complete security, let alone one like yours that remains delusional, greedy, and arrogant to this very day. Anyway we are going to publish the privatekey to decrypt our conversations afterwards.”
Blockstream has continued answering in encrypted, PGP-signed notes. The 15% figure matches the share of the original withdrawal still sitting in the attackers’ wallet, so the 10% figure implies the hackers are willing to send more funds back to the Liquid federation address, while leaving the remaining funds as an effective bug bounty.
Critics Say This Is Not White-Hat Work
Plenty of people in Bitcoin do not accept the white-hat framing the hackers have placed upon themselves. Keeping hundreds of coins and attaching a public payout demand looks, to them, like a crime in progress.
“Robbing a fancy bank, trying to keep a double digit percentage and accusing others of greed,” wrote Greg Sanders, a Bitcoin Core contributor at Spiral, the open-source Bitcoin group backed by Jack Dorsey’s Block. “Ok buddy.”
This is straight extortion.
This is not how security work is done. If these people were honest, they would have contacted Blockstream and explained the vulnerability to the security team.From there, Blockstream would have decided what was best for Liquid and its users: pause the… https://t.co/3EUgJzwCIu
— Charles Guillemet (@P3b7_) September 8, 2026
Ledger CTO Charles Guillemet was blunter. “This is straight extortion,” he posted. “This is not how security work is done. If these people were honest, they would have contacted Blockstream and explained the vulnerability to the security team.” From there, he said, Blockstream could have paused Liquid, fixed the bug, and paid a bounty. “Incentivizing this kind of conduct is irresponsible and a net negative for the whole ecosystem,” Guillemet added. “Let’s hope these people get caught.”
Pseudonymous Bitcoin Magazine technical and opinion editor Shinobi argued the attackers had boxed themselves in. “If he had just sent 100% back he could have almost certainly received a sizable bounty completely in the legal clear out of pure charity and good faith. Now he is dead to rights nailed on extortion literally conducted in public.”
SideSwap Takes Partial Blame for Loss of Funds
While that argument plays out on Bitcoin’s base chain, Liquid is trying to get the sidechain running again.
The network’s official account said an emergency Elements v23.3.4 release is out and that functionary nodes are being updated immediately. The patch hardens cache keys used for range proofs, the class of check tied to the exploit. Liquid’s current recovery outline, which it said may still change after testing, is to resume block production with peg operations still frozen, replay transactions verified as valid, then restart pegs once the network state is restored, including a return of funds.
Wow, SideSwap admitted failures? Without adding a million caveats from lawyers? 🤯 Wonder if we’ll also get a similar admission of failure from the Liquid Oversight board for not catching those risks/failures earlier. https://t.co/M6wY7XzJLz
— Anthony Towns (@ajtowns) September 9, 2026
SideSwap, whose peg-out desk processed the withdrawal, took the blame for how the bug became a mainchain loss. “The bug was in Elements, not in SideSwap. But two choices in how we ran our peg-out service turned a fault on Liquid into a loss on Bitcoin, and we take full responsibility for both.”
Those choices, SideSwap said, were keeping its peg-out authorization key online with automatic same-block payouts and running no size, velocity, or origin checks on orders. It also returned its 0.1% fee on the transaction, about 4 bitcoin, to the federation.
Blockstream also warned that scammers are already impersonating Liquid and Blockstream and telling users to “take action.” The company said it will never ask for a recovery phrase or PIN, never ask users to send funds, and never send a software-update link. Treat fake recovery addresses, “claim L-BTC” sites, lookalike domains, and unsolicited “white-hat” outreach as scams, it said, and use only official channels for updates.
Read the full article here
